摘要:
Techniques for highly parallel evaluation of XACML policies are described herein. In one embodiment, attributes are extracted from a request for accessing a resource including at least one of a user attribute and an environment attribute. Multiple individual searches are concurrently performed, one for each of the extracted attributes, in a policy store having stored therein rules and policies written in XACML, where the rules and policies are optimally stored using a bit vector algorithm. The individual search results associated with the attributes are then combined to generate a single final result using a predetermined policy combination algorithm. It is then determined whether the client is eligible to access the requested resource of the datacenter based on the single final result, including performing a layer-7 access control process, where the network element operates as an application service gateway to the datacenter. Other methods and apparatuses are also described.
摘要:
Techniques are provided for a management application in a first virtual network to start a first cloud gateway in the first virtual network. First messages are sent to a second virtual network, the first messages comprising information configured to start a second cloud gateway and a first virtual switch in the second virtual network. A connection is established between the first cloud gateway and the second cloud gateway, where the first cloud gateway, the second cloud gateway, and the first virtual switch form a first scalable cloud network element. One or more second messages are sent to the second virtual network, the one or more second messages comprising information configured to start a virtual machine and a first virtual machine interface configured to allow the virtual machine to access processing resources in the second virtual network. Data are stored that associates the virtual machine with the first virtual switch.
摘要:
A virtual space may be provided to users. In providing the virtual space to users, actions performed in the virtual space responsive to user input may be dynamically assigned a quality of service that is dependent on one or more of user value, past user action requests, past action requests cumulatively for all users, server health, and/or other criteria. This may facilitate an operator of the virtual space increasing overall user engagement and/or value, and/or provide other enhancements.
摘要:
Techniques for highly parallel evaluation of XACML policies are described herein. In one embodiment, attributes are extracted from a request for accessing a resource including at least one of a user attribute and an environment attribute. Multiple individual searches are concurrently performed, one for each of the extracted attributes, in a policy store having stored therein rules and policies written in XACML, where the rules and policies are optimally stored using a bit vector algorithm. The individual search results associated with the attributes are then combined to generate a single final result using a predetermined policy combination algorithm. It is then determined whether the client is eligible to access the requested resource of the datacenter based on the single final result, including performing a layer-7 access control process, where the network element operates as an application service gateway to the datacenter. Other methods and apparatuses are also described.
摘要:
Techniques for providing extensibility framework for processing network packets are described herein. In one embodiment, in response to a packet received at a network element, the packet is processed using a generic process for performing a first type of operations required by the packet, wherein the first type of operations is common to a type of the packet. An extended process is invoked, via an extensibility application programming interface (API), to perform a custom operation that is not common to the generic process and is not statically known to the generic process, in order to determine whether the packet is eligible to access a resource of at least one of a plurality of application servers of a datacenter, including a layer-7 access control process. The network element operates as an application service gateway for the datacenter. Other methods and apparatuses are also described.
摘要:
A programmable logic device, in accordance with an embodiment, includes a first terminal; an input buffer having a buffer input terminal and a buffer output terminal; and a multiplexer coupled to the first terminal and to the input buffer, wherein the multiplexer is adapted to selectively couple either the first terminal to the buffer input terminal or couple the buffer output terminal to the buffer input terminal.
摘要:
An apparatus and method for sorption and desorption of molecular gas contained by storage sites of graphite nano-filaments randomly disposed in three-dimensional reticulated aerogel.
摘要:
A system and method that allows an administrator to set a new password at a wireless access point, such as a traditional WAP or a wireless router. The wireless access point creates a message that includes the new password. The message is encrypted using the old password that was previously set for the wireless network. The encrypted message is wirelessly transmitted from the wireless access point to the active client devices (those clients currently accessing the wireless network). The clients decrypt the message using the old password that was previously provided to the clients. The clients retrieve the new password from the message. The clients construct a new message that is encrypted using the new password. The new message is wirelessly transmitted from the clients to the wireless access device and serves as an acknowledgement.
摘要:
Described herein are methods and devices for selectively applying fluids (particularly anesthetics) to a target tissue from within a blood vessel while minimizing the amount of fluid applied to non-target tissue. The injection catheters described herein may include an elongate body, a directional injector, and one or more holdfasts for securing the catheter before extending the injector. The methods of selectively applying anesthetic to a target structure generally include the steps of inserting an injection catheter into a body vessel, positioning the injection catheter within the body vessel near the target structure, anchoring the injection catheter before extending a directional injector from the injection catheter, and applying anesthetic from the injection catheter to the target structure.